Effective and last updated: August 18, 2026
What the website does today
You can browse the menu, build a temporary cart, view the current truck location, and view the pickup-status board. Online checkout and online payment are not enabled. Information typed into the disabled checkout form is not submitted to Lunch Box.
1. Scope
This policy explains how Lunch Box (“we,” “us,” or “our”) handles information through this public website and its staff-only admin portal. If you follow a link to another service, that service’s privacy policy applies to its handling of information.
2. Information handled by the public website
Information you choose to provide
The public site does not currently have a working contact form or online order submission. The checkout fields for name, phone, email, and notes are part of a disabled preview and are not sent to our database. If you call us, we handle the information you provide during that conversation to answer your question or arrange pickup or catering.
Technical information
GitHub Pages hosts the public files and logs visitor IP addresses for security. The site connects to Convex to load public menu, location, and status information; those requests create ordinary service logs such as request time, function name, result, and technical request metadata. Your browser also requests fonts from Google when pages load. We do not receive a visitor-level analytics dashboard from these requests.
Public order-status information
If staff use the order system, the public status board can show an active customer’s first name, order number, item summary, order status, and creation time. Phone numbers, email addresses, notes, and full names are not returned by the public status query.
3. Staff and operational information
Authorized staff may use the admin portal to manage menus, catering items, specials, pickup locations, and orders. The portal stores an admin session token in session storage for the current tab and a sidebar preference in local storage. Admin sessions have a 30-minute inactivity limit and a 12-hour absolute limit. If a staff member chooses “Use this phone’s location,” the browser asks for permission. The coordinates pass through the authenticated Convex backend to OpenStreetMap’s Nominatim service to suggest a street address. Staff can review or correct that suggestion. The coordinates and address are saved and made public only after staff confirm and publish the location.
4. Payments
This website does not currently collect card details, create a charge, or submit an online order. If online payment is added, we will update this policy and identify the active payment provider before enabling checkout.
5. How information is used
- Deliver public pages and live menu, location, and status information.
- Respond to calls and arrange pickup or catering requested directly.
- Operate and secure the staff portal and backend.
- Publish the truck location and limited active-order status information.
- Diagnose errors, prevent abuse, and maintain service reliability.
- Meet legal, accounting, safety, and recordkeeping obligations.
6. Service providers and external links
- GitHub Pages hosts the public website.
- Convex provides the database, file storage, live data, and backend functions.
- OpenStreetMap Nominatim converts staff-authorized truck coordinates into an address during check-in.
- Google Fonts supplies the typefaces requested by your browser.
- Google Maps receives information only when you open a directions link.
- DoorDash or Uber Eats receives information only if a storefront link is available and you choose to open it.
We may also disclose information when required by law, to protect people or rights, or as part of a business transfer. We do not sell personal data, use it for targeted advertising, or run behavioral advertising or analytics trackers on this site.
7. Cookies and browser storage
The public website does not currently set first-party cookies or use local or session storage. The staff-only admin portal uses the limited browser storage described above. See our Cookie Policy for details.
8. Retention
The public status board is limited by code to active paid orders created within the previous 12 hours. Removing an order from the board does not itself delete the underlying staff record. Staff can archive or delete operational records. Provider security and function logs are retained under the provider’s own schedules. We keep information only as long as reasonably needed for operations, support, security, disputes, accounting, or legal obligations.
9. Privacy requests
Depending on applicable law, you may have rights concerning personal data we hold. The Connecticut Data Privacy Act applies only when its coverage rules are met. We will nevertheless review reasonable requests to access, correct, or delete identifiable information, subject to verification and lawful exceptions. Call (860) 502-2183 or mail a written request to the address below. We do not currently sell personal data or use it for targeted advertising, so there is no such activity to opt out of.
10. Security and children
We use safeguards including restricted admin functions, hashed admin credentials, login throttling, and expiring sessions. No system is completely secure. This general-audience food-service site is not directed to children under 13, and the public site does not currently accept personal information through online ordering.
11. Changes
We will revise this policy and its date when our actual practices materially change, including before enabling online ordering, payments, analytics, or advertising technology.
Contact Lunch Box
Lunch Box
104 Baltimore St, Hartford, CT 06112
(860) 502-2183